Data processing agreement

Draft. Counsel hasn't reviewed this agreement yet, and nothing is signed before they have. Its terms may change.

This agreement applies when you use Meles to process personal data about your users. It forms part of Meles's terms, so accepting them accepts it. If you need a countersigned copy, email privacy@meles.app. How Meles protects the data is on the trust page.

Cover page

Provider ("Meles")
To be completed with counsel: the contracting party
Customer
The organisation that accepts Meles's terms
Agreement
Meles's terms of service, as Customer accepted them
Governing Member State
To be completed with counsel
Transfer mechanism
The EU standard contractual clauses and the UK Addendum (Section 3)
Provider Security Contact
privacy@meles.app
Security Policy
The security measures on the trust page, and Annex II below
Approved Subprocessors
Annex III below
Notice of a new Subprocessor
30 days, by email to the Owners of Customer's organisation

Annex I(A): the parties

Annex I(B): the processing

Categories of data subjects
People who use Customer's product or site where Customer has installed Meles's script or calls Meles's API ("end users").
Categories of personal data
  • The anonymous ID Meles's script gives each browser or app.
  • The user ID Customer assigns and the traits Customer sends, which hold whatever Customer chooses.
  • What end users do: event names and properties, page addresses, referrers and session IDs.
  • When a campaign was shown or dismissed, and in which session.
  • Their answers, including open text.
  • Campaign targeting rules that name a person.
  • The events Customer has Meles deliver to its webhooks, and each delivery's attempts.
  • Which end users were reached in each month, counted once for billing: a hash of the user ID Customer assigns, which can be matched by guessing that ID, or Meles's ID for an end user who has none.
  • Meles's own internal ID for each end user, where Meles's records point at a person: its tables, background jobs and deletion and export requests; and keyed hashes, never the values, of the identifier in a deletion or export request and of an AI agent's tool-call arguments.
Special category data
None is needed, and Customer won't send any. An open-text answer holds whatever an end user types; Customer can delete any answer, or everything about one end user.
Frequency of transfer
Continuous, while Customer uses the Service.
Nature and purpose of processing
Collecting, storing, counting and displaying the data so that Customer can show campaigns to its end users and see their results; exporting it and deleting it on Customer's instruction; and delivering it to destinations Customer connects.
Duration of processing
For the term of the Agreement, then as Section 7 says.

Annex I(C): the supervisory authority

To be completed with counsel, under Clause 13 of the EU standard contractual clauses.

Annex II: technical and organisational measures

The measures below, each with its evidence on the trust page.

Annex III: approved subprocessors

The vendors that receive Customer Personal Data. Every vendor Meles uses is on the trust page.

  • DigitalOcean

    What for
    Hosting: our servers, database, backups and file storage, and the network that delivers our script
    What it receives
    Everything Meles holds
    Where
    The United States (New York)
    Transfers from the EEA and the UK
    Certified to the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Framework, with the EU standard contractual clauses and the UK Addendum as the fallback
    Its data processing terms
    DigitalOcean's DPA
  • Sentry

    What for
    Error reports from our servers and dashboard, and uptime checks
    What it receives
    Our internal ID numbers in error reports: never a name, an email address or an answer
    Where
    The United States
    Transfers from the EEA and the UK
    Certified to the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Framework, with the EU standard contractual clauses and the UK Addendum as the fallback
    Its data processing terms
    Sentry's DPA

1. Processor and Subprocessor relationships

1.1 Meles as Processor. In situations where Customer is a Controller of the Customer Personal Data, Meles will be deemed a Processor that is Processing Personal Data on behalf of Customer.

1.2 Meles as Subprocessor. In situations where Customer is a Processor of the Customer Personal Data, Meles will be deemed a Subprocessor of the Customer Personal Data.

2. Processing

2.1 Processing Details. Annex I(B) on the Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.

2.2 Processing Instructions. Customer instructs Meles to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as may be further specified through Customer’s use of the Service; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Meles about Processing Customer Personal Data under this DPA. Meles will abide by these instructions unless prohibited from doing so by Applicable Laws. Meles will immediately inform Customer if it is unable to follow the Processing instructions. Customer has given and will only give instructions that comply with Applicable Laws.

2.3 Processing by Meles. Meles will only Process Customer Personal Data in accordance with this DPA, including the details in the Cover Page. If Meles updates the Service to update existing or include new products, features, or functionality, Meles may change the Categories of Data Subjects, Categories of Personal Data, Special Category Data, Special Category Data Restrictions or Safeguards, Frequency of Transfer, Nature and Purpose of Processing, and Duration of Processing as needed to reflect the updates by notifying Customer of the updates and changes.

2.4 Customer Processing. Where Customer is a Processor and Meles is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer’s Processing of Customer Personal Data. Customer’s agreement with its Controller will similarly require Customer to comply with all Applicable Laws that apply to Customer as a Processor. In addition, Customer will comply with the Subprocessor requirements in Customer’s agreement with its Controller.

2.5 Consent to Processing. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Meles and/or the Service, including making all disclosures, obtaining all consents, providing adequate choice, and implementing relevant safeguards required under Applicable Data Protection Laws.

2.6 Subprocessors.

(a) Meles will not provide, transfer, or hand over any Customer Personal Data to a Subprocessor unless Customer has approved the Subprocessor. The current list of Approved Subprocessors includes the identities of the Subprocessors, their country of location, and their anticipated Processing tasks. Meles will inform Customer at least 30 days in advance and in writing, by email to the Owners of Customer’s organisation in the Service, of any intended changes to the Approved Subprocessors whether by addition or replacement of a Subprocessor, which allows Customer to have enough time to object to the changes before Meles begins using the new Subprocessor(s). Meles will give Customer the information necessary to allow Customer to exercise its right to object to the change to Approved Subprocessors. Customer has 30 days after notice of a change to the Approved Subprocessors to object, otherwise Customer will be deemed to accept the changes. If Customer objects to the change within 30 days of notice, Customer and Meles will cooperate in good faith to resolve Customer’s objection or concern.

(b) When engaging a Subprocessor, Meles will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it, and (ii) consistent with the terms of Agreement.

(c) If the GDPR applies to the Processing of Customer Personal Data, (i) the data protection obligations described in this DPA (as referred to in Article 28(3) of the GDPR, if applicable) are also imposed on the Subprocessor, and (ii) Meles’s agreement with the Subprocessor will incorporate these obligations, including details about how Meles and its Subprocessor will coordinate to respond to inquiries or requests about the Processing of Customer Personal Data. In addition, Meles will share, at Customer’s request, a copy of its agreements (including any amendments) with its Subprocessors. To the extent necessary to protect business secrets or other confidential information, including personal data, Meles may redact the text of its agreement with its Subprocessor prior to sharing a copy.

(d) Meles remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data. Meles will notify Customer of any failure by its Subprocessors to fulfill a material obligation about Customer Personal Data under the agreement between Meles and the Subprocessor.

3. Restricted Transfers

3.1 Authorization. Customer agrees that Meles may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Meles transfers Customer Personal Data to a territory for which the European Commission or other relevant supervisory authority has not issued an adequacy decision, Meles will implement appropriate safeguards for the transfer of Customer Personal Data to that territory consistent with Applicable Data Protection Laws.

3.2 Ex-EEA Transfers. Customer and Meles agree that if the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the EEA to Meles outside of the EEA, and the transfer is not governed by an adequacy decision made by the European Commission, then by entering into this DPA, Customer and Meles are deemed to have signed the EEA SCCs and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the EEA SCCs, which are completed as follows:

(a) Module Two (Controller to Processor) of the EEA SCCs apply when Customer is a Controller and Meles is Processing Customer Personal Data for Customer as a Processor.

(b) Module Three (Processor to Sub-Processor) of the EEA SCCs apply when Customer is a Processor and Meles is Processing Customer Personal Data on behalf of Customer as a Subprocessor.

(c) For each module, the following applies (when applicable): (i) the optional docking clause in Clause 7 does not apply; (ii) in Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of Subprocessor changes is 30 days; (iii) in Clause 11, the optional language does not apply; (iv) all square brackets in Clause 13 are removed; (v) in Clause 17 (Option 1), the EEA SCCs will be governed by the laws of the Governing Member State; (vi) in Clause 18(b), disputes will be resolved in the courts of the Governing Member State; and (vii) the Cover Page to this DPA contains the information required in Annex I, Annex II, and Annex III of the EEA SCCs.

3.3 Ex-UK Transfers. Customer and Meles agree that if the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the United Kingdom to Meles outside of the United Kingdom, and the transfer is not governed by an adequacy decision made by the United Kingdom Secretary of State, then by entering into this DPA, Customer and Meles are deemed to have signed the UK Addendum and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the UK Addendum, which is completed as follows:

(a) Section 3.2 of this DPA contains the information required in Table 2 of the UK Addendum.

(b) Table 4 of the UK Addendum is modified as follows: neither party may end the UK Addendum as set out in Section 19 of the UK Addendum; to the extent the ICO issues a revised Approved Addendum under Section 18 of the UK Addendum, the parties will work in good faith to revise this DPA accordingly.

(c) The Cover Page contains the information required by Annex 1A, Annex 1B, Annex II, and Annex III of the UK Addendum.

3.4 Other International Transfers. For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Data Protection Act or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.

4. Security Incident Response

4.1 Upon becoming aware of any Security Incident, Meles will: (a) notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident, by email to the Owners of Customer’s organisation in the Service; (b) provide timely information about the Security Incident as it becomes known or as is reasonably requested by Customer; and (c) promptly take reasonable steps to contain and investigate the Security Incident. Meles’s notification of or response to a Security Incident as required by this DPA will not be construed as an acknowledgment by Meles of any fault or liability for the Security Incident.

5. Audit and reports

5.1 Audit Rights. Meles will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and Meles will allow for and contribute to audits, including inspections by Customer, to assess Meles’s compliance with this DPA. However, Meles may restrict access to data or information if Customer’s access to the information would negatively impact Meles’s intellectual property rights, confidentiality obligations, or other obligations under Applicable Laws. Customer acknowledges and agrees that it will only exercise its audit rights under this DPA and any audit rights granted by Applicable Data Protection Laws by instructing Meles to comply with the reporting and due diligence requirements below. Meles will maintain records of its compliance with this DPA for 3 years after the DPA ends.

5.2 Security Evidence. Meles is not audited by independent third-party auditors and holds no certification. The Security Policy names, for each security measure, the evidence that shows it. Upon written request, Meles will give Customer, on a confidential basis, that evidence, and any audit report its Subprocessors make available to Meles, so that Customer can verify Meles’s compliance with the Security Policy.

5.3 Security Due Diligence. In addition to the evidence in Section 5.2, Meles will respond to reasonable requests for information made by Customer to confirm Meles’s compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, or by giving additional information about its information security program. All such requests must be in writing and made to the Provider Security Contact and may only be made once a year.

6. Coordination and cooperation

6.1 Response to Inquiries. If Meles receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Meles will notify Customer about the request and Meles will not respond to the request without Customer’s prior consent. Examples of these kinds of inquiries and requests include a judicial or administrative or regulatory agency order about Customer Personal Data where notifying Customer is not prohibited by Applicable Law, or a request from a data subject. If allowed by Applicable Law, Meles will follow Customer’s reasonable instructions about these requests, including providing status updates and other information reasonably requested by Customer. If a data subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer’s giving of Customer Personal Data to Meles, Meles will assist Customer in fulfilling the request according to the Applicable Data Protection Law. Meles will cooperate with and provide reasonable assistance to Customer, at Customer’s expense, in any legal response or other procedural action taken by Customer in response to a third-party request about Meles’s Processing of Customer Personal Data under this DPA.

6.2 DPIAs and DTIAs. If required by Applicable Data Protection Laws, Meles will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and consultations with relevant data protection authorities, taking into consideration the nature of the Processing and Customer Personal Data.

7. Deletion of Customer Personal Data

7.1 Deletion by Customer. Meles will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Services. Meles will comply with this instruction as soon as reasonably practicable except where further storage of Customer Personal Data is required by Applicable Law. When Customer deletes a site, Meles keeps its data for 30 days, during which Customer may restore it, and then deletes it.

7.2 Deletion at DPA Expiration.

(a) After the DPA expires, Meles will return or delete Customer Personal Data at Customer’s instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law. Unless Customer instructs otherwise, Meles deletes Customer Personal Data 30 days after the DPA expires, and gives Customer an export of it if Customer asks within those 30 days; copies in Meles’s backups expire within 7 days after that. If return or destruction is impracticable or prohibited by Applicable Laws, Meles will make reasonable efforts to prevent additional Processing of Customer Personal Data and will continue to protect the Customer Personal Data remaining in its possession, custody, or control. For example, Applicable Laws may require Meles to continue hosting or Processing Customer Personal Data.

(b) If Customer and Meles have entered the EEA SCCs or the UK Addendum as part of this DPA, Meles will only give Customer the certification of deletion of Personal Data described in Clause 8.1(d) and Clause 8.5 of the EEA SCCs if Customer asks for one.

8. Limitation of liability

8.1 Liability Caps and Damages Waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party’s total cumulative liability to the other party arising out of or related to this DPA will be subject to the waivers, exclusions, and limitations of liability stated in the Agreement.

8.2 Related-Party Claims. Any claims made against Meles or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.

8.3 Exceptions. This DPA does not limit any liability to an individual about the individual’s data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability between the parties for violations of the EEA SCCs or UK Addendum.

9. Conflicts between documents

9.1 This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency: (1) the EEA SCCs or the UK Addendum, (2) this DPA, and then (3) the Agreement.

10. Term of agreement

10.1 This DPA will start when Meles and Customer agree to a Cover Page for the DPA and sign or electronically accept the Agreement and will continue until the Agreement expires or is terminated. However, Meles and Customer will each remain subject to the obligations in this DPA and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Meles and Meles stops Processing Customer Personal Data.

11. Definitions

11.1 “Applicable Laws” means the laws, rules, regulations, court orders, and other binding requirements of a relevant government authority that apply to or govern a party.

11.2 “Applicable Data Protection Laws” means the Applicable Laws that govern how the Service may process or use an individual’s personal information, personal data, personally identifiable information, or other similar term.

11.3 “Controller” will have the meaning(s) given in the Applicable Data Protection Laws for the company that determines the purpose and extent of Processing Personal Data.

11.4 “Cover Page” means a document that is signed or electronically accepted by the parties that incorporates these DPA Standard Terms and identifies Meles, Customer, and the subject matter and details of the data processing. For this DPA as published, it is the Cover Page section of the page these terms appear on.

11.5 “Customer Personal Data” means Personal Data that Customer uploads or provides to Meles as part of the Service and that is governed by this DPA.

11.6 “DPA” means these DPA Standard Terms, the Cover Page between Meles and Customer, and the policies and documents referenced in or attached to the Cover Page.

11.7 “EEA SCCs” means the standard contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the European Council.

11.8 “European Economic Area” or “EEA” means the member states of the European Union, Norway, Iceland, and Liechtenstein.

11.9 “GDPR” means European Union Regulation 2016/679 as implemented by local law in the relevant EEA member nation.

11.10 “Personal Data” will have the meaning(s) given in the Applicable Data Protection Laws for personal information, personal data, or other similar term.

11.11 “Processing” or “Process” will have the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.

11.12 “Processor” will have the meaning(s) given in the Applicable Data Protection Laws for the company that Processes Personal Data on behalf of the Controller.

11.13 “Restricted Transfer” means (a) where the GDPR applies, a transfer of personal data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; and (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not subject to adequacy regulations adopted pursuant to Section 17A of the United Kingdom Data Protection Act 2018.

11.14 “Security Incident” means a Personal Data Breach as defined in Article 4 of the GDPR.

11.15 “Service” means the product and/or services described in the Agreement.

11.16 “Special Category Data” will have the meaning given in Article 9 of the GDPR.

11.17 “Subprocessor” will have the meaning(s) given in the Applicable Data Protection Laws for a company that, with the approval and acceptance of Controller, assists the Processor in Processing Personal Data on behalf of the Controller.

11.18 “UK GDPR” means European Union Regulation 2016/679 as implemented by section 3 of the United Kingdom’s European Union (Withdrawal) Act of 2018 in the United Kingdom.

11.19 “UK Addendum” means the international data transfer addendum to the EEA SCCs issued by the Information Commissioner for Parties making Restricted Transfers under S119A(1) Data Protection Act 2018.

Where these terms come from

Sections 1 to 11 are adapted from Common Paper's Data Processing Agreement Standard Terms, used under CC BY 4.0. Our changes: